<?php ob_start(); session_start();
include("../../Connections/connect_admin.php");
if($_POST['task']=='add')
{
	$user=$_SESSION['username'];
	$name=$_POST['advname'];
	$desc=$_POST['description'];
	$position=intval($_POST['position']);
	$link=$_POST['link'];
	$target_path = "../../Images/Advertisement/";
	
	if(isset($_FILES['updfile'])) 
	{
	$target_path = $target_path.basename( $_FILES['updfile']['name']); 
	if ( !preg_match('/\.(jpg|gif|png|swf)$/i',basename($_FILES['updfile']['name'] )) )
	{ header('location:../Advertisement.php?e=1');}
	if($_FILES['updfile']['size']>1024*1024)
	{header('location:../Advertisement.php?e=1');}
	if (file_exists($target_path))
		  {
		  	unlink($target_path);
		  }
	if(move_uploaded_file($_FILES['updfile']['tmp_name'], $target_path)) 
	{
		$file=basename( $_FILES['updfile']['name']);
		
	} else{
		header('location:../Advertisement.php?e=1');
	}
	}
	$fname=$_FILES['updfile']['name'];
	list($txt, $ext) = explode(".", $fname);
	$type=0;
	if($ext=="swf")
	{
		$type=1;
	}
	$query="INSERT INTO advertisement (AdvertiseName, Description, FileType, FilePath,`Position`, Link, CreatedUser) VALUES('$name','$desc',$type,'$fname',$position,'$link','$user')";
	if(mysql_query($query))
	{
		header('location:../Advertisement.php?e=0');
	}
	else
	{
		header('location:../Advertisement.php?e=1');
	}

}
else if($_POST['task']=='update')
{
	$id=intval($_POST['advid']);
	$name=$_POST['advname'];
	$desc=$_POST['description'];
	$position=intval($_POST['position']);
	$link=$_POST['link'];
	$query="UPDATE advertisement SET AdvertiseName = '$name',Description = '$desc',`Position` = $position,Link = '$link' ";
	$target_path = "../../Images/Advertisement/";
	
	if(isset($_FILES['updfile'])) 
	{
		$target_path = $target_path.basename( $_FILES['updfile']['name']); 
		if ( !preg_match('/\.(jpg|gif|png|swf)$/i',basename($_FILES['updfile']['name'] )) )
		{ header('location:../Advertisement.php?e=3');}
		if($_FILES['updfile']['size']>1024*1024)
		{header('location:../Advertisement.php?e=3');}
		if (file_exists($target_path))
			  {
				unlink($target_path);
			  }
		if(move_uploaded_file($_FILES['updfile']['tmp_name'], $target_path)) 
		{
			$file=basename( $_FILES['updfile']['name']);
			list($txt, $ext) = explode(".", $file);
			$type=0;
			if($ext=="swf")
			{
				$type=1;
			}
			$query.=" ,FilePath = '$file',FileType = $type ";
			
		} else{
			header('location:../Advertisement.php?e=3');
		}
	}
	
	
	$query.=" WHERE AdvertiseID=$id";
	if(mysql_query($query))
	{
		header('location:../Advertisement.php?e=2');
	}
	else
	{
		header('location:../Advertisement.php?e=3');
	}
}
else if($_POST['task']=='delete')
{
	$id=intval($_POST['advid']);
	$user=$_SESSION['username'];
	$query="UPDATE advertisement SET IsDeleted = 1,DeletedDate = NOW(),DeletedUser = '$user' WHERE AdvertiseID=$id";
	if(mysql_query($query))
	{
		$response=array('ok'=>true,'msg'=> 'Xóa mục quảng cáo Thành Công');
	}
	else
	{
		$response=array('ok'=>false,'msg'=> 'Xóa mục quảng cáo Thất Bại!!!');
	}
	echo json_encode($response);
}

?>